Nortel Networks NN46110-602 Uživatelský manuál

Procházejte online nebo si stáhněte Uživatelský manuál pro Sítě Nortel Networks NN46110-602. Nortel Networks NN46110-602 User's Manual Uživatelská příručka

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 230
  • Tabulka s obsahem
  • ŘEŠENÍ PROBLÉMŮ
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků

Shrnutí obsahu

Strany 1 - Troubleshooting

Version 7.00Part No. NN46110-602315900-E Rev 01February 2007Document status: Standard600 Technology Park DriveBillerica, MA 01821-4130Nortel VPN Rout

Strany 2 - Statement of conditions

10 ContentsNN46110-602Appendix BUsing serial PPP . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 165Establ

Strany 3

100 Chapter 4 TroubleshootingNN46110-602Authorization failed. Please try again.Description: This error occurs when the wrong authentication credenti

Strany 4

Chapter 4 Troubleshooting 101Nortel VPN Router TroubleshootingAction: To ensure that the most current data is loaded:1 Close the current policy, if

Strany 5 - Contents

102 Chapter 4 TroubleshootingNN46110-602

Strany 6

103Nortel VPN Router TroubleshootingChapter 5Packet capture Packet capture (PCAP) is a troubleshooting tool that network administrators and customer s

Strany 7

104 Chapter 5 Packet captureNN46110-602PCAP initially occurs to the RAM buffer. A low priority task writes the RAM buffer to disk files, called the

Strany 8

Chapter 5 Packet capture 105Nortel VPN Router Troubleshooting• limit the traffic that the filters capture• automatically start and stop packet captu

Strany 9

106 Chapter 5 Packet captureNN46110-602Capture typesThe VPN Router captures packets from the following sources:• Physical interfaces, including the

Strany 10

Chapter 5 Packet capture 107Nortel VPN Router TroubleshootingTunnel captures saved to disk are encapsulated with raw IP encapsulation. When you conv

Strany 11

108 Chapter 5 Packet captureNN46110-602A global IP capture object captures packets beginning from the IP header; no Layer 2 header is saved in the c

Strany 12 - Contents

Chapter 5 Packet capture 109Nortel VPN Router Troubleshooting•A start trigger causes the system to wait for a specific packet before it starts savin

Strany 13

Contents 11Nortel VPN Router TroubleshootingIPX client . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Strany 14 - Figures

110 Chapter 5 Packet captureNN46110-602You can create new capture objects until the maximum block size reaches 25 Mbyte. (The VPN Router does not al

Strany 15

Chapter 5 Packet capture 111Nortel VPN Router Troubleshooting• Delete a capture object or capture files when you no longer need them to free up memo

Strany 16 - Tables

112 Chapter 5 Packet captureNN46110-6026 Enter the administrator’s user name and password.Please enter the administrator's user name: adminPlea

Strany 17 - Text conventions

Chapter 5 Packet capture 113Nortel VPN Router Troubleshooting10 If you want, you can now change the VPN Router administrator password.CES#configure

Strany 18 - show ntp associations

114 Chapter 5 Packet captureNN46110-602For example, enter:CES(capture-ethernet)#filepath /ideX/system/log Setting the size of the RAM bufferTo set t

Strany 19 - Acronyms

Chapter 5 Packet capture 115Nortel VPN Router TroubleshootingFor example, enter:CES(capture-ethernet)#maxfiles 99Saving captured dataTo set the PCAP

Strany 20 - 20 Preface

116 Chapter 5 Packet captureNN46110-602For example, enter the following command:CES# capture add test1 ? atm ATM interface capture bri

Strany 21 - Related publications

Chapter 5 Packet capture 117Nortel VPN Router TroubleshootingTo configure a capture object:1 Navigate to Capture Configuration mode by entering the

Strany 22 - How to get help

118 Chapter 5 Packet captureNN46110-602Tunnel capture parametersCapture objects for tunnels have several unique parameters. The following example cr

Strany 23 - Preface 23

Chapter 5 Packet capture 119Nortel VPN Router TroubleshootingGlobal IP parametersThe configurable parameters for the global IP capture object are th

Strany 24 - 24 Preface

12 ContentsNN46110-602

Strany 25 - New in this release

120 Chapter 5 Packet captureNN46110-602In the following example, the show capture command is run with no object name to display a list of all the ca

Strany 26 - PCAP enhancements

Chapter 5 Packet capture 121Nortel VPN Router TroubleshootingSample packet capture configurationsThis section provides sample configurations and the

Strany 27 - VPN Router administration

122 Chapter 5 Packet captureNN46110-602To view the status of the running capture object, as well as its configuration, use the show capture command.

Strany 28

Chapter 5 Packet capture 123Nortel VPN Router TroubleshootingTo create and use this capture object, you run commands like the ones illustrated in th

Strany 29 - Dynamic password

124 Chapter 5 Packet captureNN46110-602After Telnet traffic activates the stop trigger, the show capture command resembles the following example. Th

Strany 30 - File management

Chapter 5 Packet capture 125Nortel VPN Router Troubleshooting4 Exit Capture Configuration mode.5 Start the capture.CES#capture add test-remote-ip tu

Strany 31

126 Chapter 5 Packet captureNN46110-6023 Click ethereal-setup-n.nn.n.exe.4 Click a download site and save the executable file on your hard drive.5 D

Strany 32

Chapter 5 Packet capture 127Nortel VPN Router Troubleshooting6 Enter the password that you entered when you enabled packet capture (see “Enabling pa

Strany 33 - <hh:mm:ss> [send-one]

128 Chapter 5 Packet captureNN46110-602T1 frame relay capture:editcap -F ngsniffer d:\pcap\fr.cap frelay.syc5 From Sniffer Pro, open the .enc file o

Strany 34 - To configure the amount:

Chapter 5 Packet capture 129Nortel VPN Router TroubleshootingTo delete a packet capture object:1 Display all configured capture objects on the VPN R

Strany 35 - Status and logging

13Nortel VPN Router TroubleshootingFiguresFigure 1 Admin > SNMP Traps window . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 33

Strany 36 - Sessions

130 Chapter 5 Packet captureNN46110-602

Strany 37 - Statistics

131Nortel VPN Router TroubleshootingAppendix AMIB supportThe VPN Router supports the management information base (MIB) for use with network management

Strany 38 - Accounting

132 Appendix A MIB supportNN46110-602RFC 1724—RIP Version 2 MIB ExtensionThe VPN Router supports RFC 1724, RIP Version 2 MIB Extension. As stated in

Strany 39 - Data collection task

Appendix A MIB support 133Nortel VPN Router TroubleshootingRFC 2787—VRRP MIBThe VPN Router supports RFC 2787, Definitions of Managed Objects for the

Strany 40

134 Appendix A MIB supportNN46110-602RFC 1573—IanaIfType MIB This MIB contains the enumerations for rfc2233 ifTable.ifType. These enumerations descr

Strany 41 - Event log

Appendix A MIB support 135Nortel VPN Router Troubleshooting— hrNetworkTable— hrPrinterTable— hrDiskStorageTablehrDiskStorageCapacity— hrPartitionTab

Strany 42 - Figure 2 Event logs

136 Appendix A MIB supportNN46110-602RFC2863 Interface MIB (64 bit counters support)The support for the following entries was added in the interface

Strany 43

Appendix A MIB support 137Nortel VPN Router Troubleshootingcestraps.mib—Nortel proprietary MIBThis section lists the contents of the cestraps.mib, t

Strany 44

138 Appendix A MIB supportNN46110-602-- The second means packets were dropped due to a detected spoofed address-- The third should never happen, but

Strany 45 - Security log

Appendix A MIB support 139Nortel VPN Router Troubleshootingnewoak.mibThis section provides the contents of the newoak.mib, which defines the newoak

Strany 46 - Configuration log

14 FiguresNN46110-602

Strany 47 - Administrative tasks

140 Appendix A MIB supportNN46110-602Hardware-related trapshardwareTrapInfo OBJECT IDENTIFIER::= {ContivitySnmpTraps 1}-- Trap #1001 hardDisk1Status

Strany 48 - Recovery

Appendix A MIB support 141Nortel VPN Router TroubleshootingACCESS read-onlySTATUS mandatoryDESCRIPTION "Status of the first CPU fan."::=

Strany 49

142 Appendix A MIB supportNN46110-602ACCESS read-onlySTATUS mandatoryDESCRIPTION "Status of 2.5VA power."::= {hardwareTrapInfo 12}-- Tra

Strany 50

Appendix A MIB support 143Nortel VPN Router TroubleshootingACCESS read-onlySTATUS mandatoryDESCRIPTION "The chassis intrusion sensor indicate

Strany 51

144 Appendix A MIB supportNN46110-602Server-related trapsserverTrapInfo OBJECT IDENTIFIER::= {ContivitySnmpTraps 2} -- Trap #3001radiusAcctServer OB

Strany 52

Appendix A MIB support 145Nortel VPN Router TroubleshootingACCESS read-onlySTATUS mandatoryDESCRIPTION "Status of DNS Server."::= {serve

Strany 53

146 Appendix A MIB supportNN46110-602Software-related trapssoftwareTrapInfo OBJECT IDENTIFIER::= {ContivitySnmpTraps 3}-- Trap #5001NetBuffers OBJEC

Strany 54

Appendix A MIB support 147Nortel VPN Router TroubleshootingIntrusion-related trapsintrusionTrapInfo OBJECT IDENTIFIER::= {ContivitySnmpTraps 5}-- Tr

Strany 55

148 Appendix A MIB supportNN46110-602Information passed with every trapSeverityLevel OBJECT-TYPESYNTAX INTEGER{fatal(1),major(2),minor(3),informatio

Strany 56

Appendix A MIB support 149Nortel VPN Router TroubleshootingTable 3 provides trap categories and explanations.Table 3 Trap categories Hardware1.3.

Strany 57

15Nortel VPN Router TroubleshootingTablesTable 1 Field IDs for data collection records . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 40Ta

Strany 58

150 Appendix A MIB supportNN46110-602Table 4 provides descriptions for the VPN Router traps.Server1.3.6.1.4.1.2505.1.2.0.3007 snmpServerTrap1.3.6.1.

Strany 59

Appendix A MIB support 151Nortel VPN Router TroubleshootingProprietary 1.3.6.1.4.1.2505.1.1.0.1009 fiveVoltsPosStatusTrap Status of the +5 Volt powe

Strany 60 - Upgrading the software

152 Appendix A MIB supportNN46110-602Proprietary 1.3.6.1.4.1.2505.1.1.0.10020 t1WANStatusTrap Status of T1 WAN card(s);Possible values for Wanic:Ale

Strany 61 - Checking available disk space

Appendix A MIB support 153Nortel VPN Router TroubleshootingProprietary 1.3.6.1.4.1.2505.1.1.0.10022 hwAccelTrap Status of hardware accelerator card.

Strany 62

154 Appendix A MIB supportNN46110-602Proprietary 1.3.6.1.4.1.2505.1.1.0.10024 v90WANStatusTrap Status of V.90 Interface card.Possible Values:Please

Strany 63 - Backing up system files

Appendix A MIB support 155Nortel VPN Router TroubleshootingProprietary 1.3.6.1.4.1.2505.1.1.0.10026 serUartStatusTrap Status of Serial (COM) port/in

Strany 64 - Retrieving the new software

156 Appendix A MIB supportNN46110-602Proprietary 1.3.6.1.4.1.2505.1.2.0.3005 loadBalancingServerTrap Status of Load Balancing Server.Proprietary 1.3

Strany 65 - Figure 9 FTP menu example

Appendix A MIB support 157Nortel VPN Router TroubleshootingProprietary 1.3.6.1.4.1.2505.1.2.0.30014 dhcpServerTrap Status of DHCP Server.Possible Va

Strany 66 - Before completing the upgrade

158 Appendix A MIB supportNN46110-602Proprietary 1.3.6.1.4.1.2505.1.3.0.5007 sslVpnStatusTrap Status of SSL-VPN Accelerator. Possible Values: Disa

Strany 67 - Applying the software

Appendix A MIB support 159Nortel VPN Router TroubleshootingStandard 1.3.6.1.2.1.11.0.2 linkDown A linkDown trap signifies that the sending protocol

Strany 68

16 TablesNN46110-602

Strany 69 - Chapter 4

160 Appendix A MIB supportNN46110-602Standard 1.3.6.1.2.1.11.0.3 linkUp A linkUp trap signifies that the sending protocol entity recognizes that one

Strany 70 - Troubleshooting tools

Appendix A MIB support 161Nortel VPN Router TroubleshootingStandard 1.3.6.1.2.1.11.0.5 authenticationFailure n authenticationFailure trap signifies

Strany 71 - Other tools

162 Appendix A MIB supportNN46110-602Standard 1.3.6.1.2.1.11.0.2 linkDown A linkDown trap signifies that the sending protocol entity recognizes a fa

Strany 72 - Solving connectivity problems

Appendix A MIB support 163Nortel VPN Router TroubleshootingStandard 1.3.6.1.2.1.11.0.3 linkUp A linkUp trap signifies that the sending protocol enti

Strany 73 - Extranet connection problems

164 Appendix A MIB supportNN46110-602Standard 1.3.6.1.2.1.11.0.5 authenticationFailure An authenticationFailure trap signifies that the SNMPv2 enti

Strany 74 - Authentication failed

165Nortel VPN Router TroubleshootingAppendix BUsing serial PPPYou use Serial Point-to-Point Protocol (PPP) to manage the VPN Router from a remote loca

Strany 75 - Extranet connection lost

166 Appendix B Using serial PPPNN46110-602Setting up a Dial-Up Networking connectionTo establish a Serial PPP connection using a Microsoft Dial-Up N

Strany 76

Appendix B Using serial PPP 167Nortel VPN Router TroubleshootingSetting up the modemThe following procedure assumes that you are using a 3Com/US Rob

Strany 77 - Network browsing problems

168 Appendix B Using serial PPPNN46110-602to access all management services (HTTP, Telnet, FTP, SNMP) through the Web interface. Once you establish

Strany 78 - VPN Client connection

Appendix B Using serial PPP 169Nortel VPN Router TroubleshootingDialing in to the VPN RouterUse the standard dial-up networking procedure to connect

Strany 79 - Diagnosing WAN link problems

17Nortel VPN Router TroubleshootingPrefaceThis guide provides information about how to manage and troubleshoot the Nortel VPN Router. Before you begin

Strany 80 - Check the T1/V.35 interface

170 Appendix B Using serial PPPNN46110-602Cause:You were dialed in and managing the VPN Router remotely using PPP and you changed the baud rate and

Strany 81 - Check the PPP layer

Appendix B Using serial PPP 171Nortel VPN Router TroubleshootingAction:Make sure that the modem that is connected to the VPN Router has hardware flo

Strany 82 - Solving performance problems

172 Appendix B Using serial PPPNN46110-602

Strany 83

173Nortel VPN Router TroubleshootingAppendix CSystem messagesSystem forwarding (syslog) uses the system logging daemon (syslogd) to forward informatio

Strany 84

174 Appendix C System messagesNN46110-602tCert: Shutdown completeDescription: This informational message indicates that the task responsible for cer

Strany 85

Appendix C System messages 175Nortel VPN Router Troubleshooting2 Manually verify the tunnel-related certificate fingerprints. Perform this procedure

Strany 86

176 Appendix C System messagesNN46110-602Action: Make sure the PFS settings on both sides match. Either enable PFS on the remote side, or disable PF

Strany 87 - Parameters

Appendix C System messages 177Nortel VPN Router TroubleshootingISAKMP [13] Error notification (Authentication failure) received from xxx (a.b.c.d)De

Strany 88 - (with tunnels)?

178 Appendix C System messagesNN46110-602ISAKMP [13] Invalid ID information in message from xxx (a.b.c.d)Description: One side of the connection is

Strany 89

Appendix C System messages 179Nortel VPN Router TroubleshootingAction: Remove the existing static route or change the route for the remote network t

Strany 90

18 PrefaceNN46110-602braces ({}) Indicate required elements in syntax descriptions where there is more than one option. You must choose only one of

Strany 91 - Additional information

180 Appendix C System messagesNN46110-602No matching trusted CA certsDescription: None of the certificates in the chain are trusted CA certificates.

Strany 92 - Solving general problems

Appendix C System messages 181Nortel VPN Router TroubleshootingAction: Make sure the backup file has an 8.3 file name.LDIF file: could not restore x

Strany 93 - Enabling Web browser options

182 Appendix C System messagesNN46110-602CaAuthServerCollection: authenticate xxx cert [xxx] invalid signature by [xxx] - xxxDescription: The certif

Strany 94 - Web browser error messages

Appendix C System messages 183Nortel VPN Router TroubleshootingAction: Start the LDAP server, or change the external LDAP server configuration to ma

Strany 95 - Document not found message

184 Appendix C System messagesNN46110-602Action: Start the LDAP server, or change the external LDAP server configuration to make it accessible.Error

Strany 96 - System problems

Appendix C System messages 185Nortel VPN Router Troubleshootingxxx xxx being referenced by xxxDescription: The LDAP entry is referenced by another L

Strany 97 - DHCP server

186 Appendix C System messagesNN46110-602Session: xxx[xxx]:xxx xxx auth method not allowedDescription: The authentication method of the incoming req

Strany 98 - Solving routing problems

Appendix C System messages 187Nortel VPN Router TroubleshootingSession: xxx[xxx]:xxx IP address assignment failedDescription: An address cannot be a

Strany 99 - Solving firewall problems

188 Appendix C System messagesNN46110-602Session: xxx[xxx]:xxx account not allowed nowDescription: The session request is outside the permitted hour

Strany 100 - NN46110-602

Appendix C System messages 189Nortel VPN Router TroubleshootingSession: xxx[xxx]:xxx invalid password—master admin authentication failedDescription:

Strany 101

Preface 19Nortel VPN Router TroubleshootingAcronymsThis guide uses the following acronyms: vertical line ( | ) Separates choices for command keywor

Strany 102

190 Appendix C System messagesNN46110-602Session: xxx[xxx]:xxx pool address [xxx] already in useDescription: The returned static pool address is cur

Strany 103 - Packet capture

Appendix C System messages 191Nortel VPN Router TroubleshootingRADIUS accounting messagesRADIUS: Cannot send accounting request to <server-name&g

Strany 104 - PCAP features

192 Appendix C System messagesNN46110-602RADIUS: network socket failure with <server-name>, recvfrom error: <error>Description: This mes

Strany 105 - File format

Appendix C System messages 193Nortel VPN Router TroubleshootingAction: Retry authentication attempt and verify that RADIUS server packets are proper

Strany 106 - Capture types

194 Appendix C System messagesNN46110-602RADIUS authentication messagesRADIUS: Cannot send request to <server-name>, possibly due to DNS trans

Strany 107 - Global IP captures

Appendix C System messages 195Nortel VPN Router TroubleshootingRADIUS: <server-name> server timed out authenticating <user-name>Descript

Strany 108 - Filters and triggers

196 Appendix C System messagesNN46110-602RADIUS: <server-name> sent invalid response packet for <user-name>Description: This message ind

Strany 109 - Memory considerations

Appendix C System messages 197Nortel VPN Router TroubleshootingAction: Verify that the shared secrets match.RADIUS: <server-name> sent packet

Strany 110 - Performance considerations

198 Appendix C System messagesNN46110-602RADIUS: <user-name> access DENIED by server <server-name>Description: This message indicates th

Strany 111

Appendix C System messages 199Nortel VPN Router TroubleshootingAction: No action required.Closing OSPF-RTM connectionDescription: OSPF closed the RT

Strany 112

2 NN46110-602Copyright © 2007 Nortel Networks. All rights reserved.The information in this document is subject to change without notice. The statem

Strany 113 - Setting the PCAP file path

20 PrefaceNN46110-602L2TP Layer 2 Tunneling ProtocolLAN local area networkLDAP Lightweight Directory Access ProtocolNAT Network Address Translation

Strany 114

200 Appendix C System messagesNN46110-602Can not accept x.x.x.x as router idDescription: OSPF can not accept the given router ID in the Routing >

Strany 115 - Creating a capture object

Appendix C System messages 201Nortel VPN Router TroubleshootingVR xxx: Starting xxx as Backup for xxxDescription: Logged when starting as a backup f

Strany 116 - Configuring a capture object

202 Appendix C System messagesNN46110-602Unable to get configuration for VR xxxDescription: This is an error event that is logged when VRRP is enabl

Strany 117 - when buffer gets full

Appendix C System messages 203Nortel VPN Router TroubleshootingRIP xxx: Circuit xxx deletedDescription: Logged when the RIP circuit is deleted. The

Strany 118 - Tunnel capture parameters

204 Appendix C System messagesNN46110-602RIP xxx: Unable to spawn timer task xxx for RIPDescription: Logged when RIP fails to spawn the timer task.

Strany 119 - Global IP parameters

Appendix C System messages 205Nortel VPN Router TroubleshootingInterface [nnn] replaced, deleting from configDescription: This indicates the card ty

Strany 120

206 Appendix C System messagesNN46110-602

Strany 121

207Nortel VPN Router TroubleshootingAppendix DConfiguring for interoperabilityThis chapter explains the requirements and procedures for setting up dif

Strany 122

208 Appendix D Configuring for interoperabilityNN46110-602Figure 11 VPN Router and Cisco 2514 network topology

Strany 123

Appendix D Configuring for interoperability 209Nortel VPN Router TroubleshootingThe following is a show config command:Cisco2514# show configUsing 1

Strany 124

Preface 21Nortel VPN Router TroubleshootingRelated publicationsFor more information about the Nortel VPN Router, see the following publications:• R

Strany 125 - Installing Ethereal software

210 Appendix D Configuring for interoperabilityNN46110-602dialer-list 1 protocol ipx permitsnmp-server community public ROline con 0line aux 0line v

Strany 126 - CES#capture ethernet1 stop

Appendix D Configuring for interoperability 211Nortel VPN Router TroubleshootingConfiguring the SafeNet/Soft-PK Security Policy Database Editor, Ver

Strany 127

212 Appendix D Configuring for interoperabilityNN46110-602Connecting to IRE SafeNET/Soft-PK Security Policy ClientTo set up the VPN Router to establ

Strany 128

Appendix D Configuring for interoperability 213Nortel VPN Router Troubleshooting• 8.1.10.42The SafeNet/Soft PX Security Policy Editor dialog box app

Strany 129

214 Appendix D Configuring for interoperabilityNN46110-602The SafeNet/Soft-PK Security Policy Editor dialog box appears. 10 From Security Policy: Se

Strany 130

Appendix D Configuring for interoperability 215Nortel VPN Router Troubleshooting• Authentication Method: Pre-Shared key• Encrypt Alg: DES•Hash Alg:

Strany 131 - MIB support

216 Appendix D Configuring for interoperabilityNN46110-6029 For some vendors, if you want to turn off Vendor ID and/or Perfect Forward Secrecy (PFS)

Strany 132 - RFC 2667—IP Tunnel MIB

Appendix D Configuring for interoperability 217Nortel VPN Router TroubleshootingConsiderations for using third-party clientsThere are several consid

Strany 133 - RFC 2737—Entity MIB

218 Appendix D Configuring for interoperabilityNN46110-602• Load Balancing—Traditional load balancers often do not work with the IPsec protocol beca

Strany 134 - RFC2790—Host Resources MIB

Appendix D Configuring for interoperability 219Nortel VPN Router Troubleshooting(are correctly decrypted, and authenticated) are accepted; other pac

Strany 135 - RFC2495—DS1 MIB

22 PrefaceNN46110-602Hard-copy technical manualsYou can print selected technical manuals and release notes free, directly from the Internet. Go to

Strany 136 - VPN Router MIB

220 Appendix D Configuring for interoperabilityNN46110-602then select a default server certificate from the list. You configure servers from the Sys

Strany 137 - Appendix A MIB support 137

Appendix D Configuring for interoperability 221Nortel VPN Router TroubleshootingFigure 13 Split tunneling exampleTo configure the VPN Router as a

Strany 138 - 138 Appendix A MIB support

222 Appendix D Configuring for interoperabilityNN46110-6026 Selections in the Encryption fields are dependent on the type of encryption that your th

Strany 139 - Router model

Appendix D Configuring for interoperability 223Nortel VPN Router TroubleshootingNetwork addresses form the basis of the IPX internetwork addressing

Strany 140 - Hardware-related traps

224 Appendix D Configuring for interoperabilityNN46110-602Windows 95 and Windows 98 When running Windows 95 or Windows 98, load the intraNetWare* cl

Strany 141 - Appendix A MIB support 141

Appendix D Configuring for interoperability 225Nortel VPN Router TroubleshootingFigure 14 IPX topologyNote: The private LAN can also carry IP and

Strany 142 - 142 Appendix A MIB support

226 Appendix D Configuring for interoperabilityNN46110-602

Strany 143 - Appendix A MIB support 143

Nortel VPN Router Troubleshooting227IndexAaccountingdata 40records 38, 39accounting log 38active sessions 96ActiveX Scripts 93administrators

Strany 144 - Server-related traps

228 IndexNN46110-602SSL 179event log 35, 41ExternalDHCP server 97extinctioninterval 84timeout 84Extranet Accessclient monitor 70connectio

Strany 145 - Appendix A MIB support 145

Index 229Nortel VPN Router Troubleshootingmodem hardware errors 82MS-DOS naming convention 97multiple Help windows 95NNetBEUI 77, 83NetBIOS

Strany 146 - Login-related traps

Preface 23Nortel VPN Router TroubleshootingGetting help from the Nortel Web siteThe best way to get technical support for Nortel products is from t

Strany 147 - System-related traps

230 IndexNN46110-602RADIUS accounting 191RADIUS authentication 194routing 198security 181SSL 179TT1/V.35 interface 80technical publicatio

Strany 148 - 148 Appendix A MIB support

24 PrefaceNN46110-602Getting help through a Nortel distributor or reseller If you purchased a service contract for your Nortel product from a distr

Strany 149 - Table 3 Trap categories

25Nortel VPN Router TroubleshootingNew in this releaseThe following section details what is new in Nortel VPN Router Troubleshooting for Release 7.0.F

Strany 150 - 150 Appendix A MIB support

26 New in this releaseNN46110-602Automatic backupsYou can now back up a file or a directory, as well as trigger a backup, when a file changes. Prev

Strany 151 - Appendix A MIB support 151

27Nortel VPN Router TroubleshootingChapter 1VPN Router administrationThis chapter introduces administrator settings, tools, system configuration, and

Strany 152 - 152 Appendix A MIB support

28 Chapter 1 VPN Router administrationNN46110-602You use the Administrator Settings window to do the following:• change the primary administrator us

Strany 153 - Appendix A MIB support 153

Chapter 1 VPN Router administration 29Nortel VPN Router TroubleshootingDynamic passwordTwo types of administrative users exist on the VPN Router: •

Strany 154 - 154 Appendix A MIB support

3Nortel VPN Router TroubleshootingPortions of the code in this software product may be Copyright © 1988, Regents of the University of California.

Strany 155 - Appendix A MIB support 155

30 Chapter 1 VPN Router administrationNN46110-602The Traceroute tool measures a network round-trip delay. Messages are sent per hop and the wait occ

Strany 156 - 156 Appendix A MIB support

Chapter 1 VPN Router administration 31Nortel VPN Router TroubleshootingSimple Network Management Protocol (SNMP)Use the Admin > SNMP window to do

Strany 157 - Appendix A MIB support 157

32 Chapter 1 VPN Router administrationNN46110-602The traps displayed on the group windows—in particular the Hardware Trap Configuration and the Serv

Strany 158 - 158 Appendix A MIB support

Chapter 1 VPN Router administration 33Nortel VPN Router TroubleshootingFigure 1 Admin > SNMP Traps window2 Enter a host name or IP address in

Strany 159 - Appendix A MIB support 159

34 Chapter 1 VPN Router administrationNN46110-602To configure the amount:CES(config)#ip local pool exhausted-amount <amount>

Strany 160 - 160 Appendix A MIB support

35Nortel VPN Router TroubleshootingChapter 2Status and loggingThe Status windows show which users are logged on, their traffic demands, and a summary

Strany 161 - Appendix A MIB support 161

36 Chapter 2 Status and loggingNN46110-602Most events are sent to the event log first. Significant events from the event log are sent to the system

Strany 162 - 162 Appendix A MIB support

Chapter 2 Status and logging 37Nortel VPN Router TroubleshootingIf you have multiple VPN Routers throughout the world, use the Greenwich Mean Time (

Strany 163 - Appendix A MIB support 163

38 Chapter 2 Status and loggingNN46110-602Accounting The accounting log provides information about user sessions. This log provides last and first n

Strany 164 - 164 Appendix A MIB support

Chapter 2 Status and logging 39Nortel VPN Router TroubleshootingThe data collection system stores records in text-based files stored in the system/d

Strany 165 - Using serial PPP

4 NN46110-6023. Limitation of Remedies. IN NO EVENT SHALL NORTEL NETWORKS OR ITS AGENTS OR SUPPLIERS BE LIABLE FOR ANY OF THE FOLLOWING: a) DAMAGES

Strany 166

40 Chapter 2 Status and loggingNN46110-602• Summary file that always has exactly five records containing summary data in a file called summary.dc. T

Strany 167 - Setting up the VPN Router

Chapter 2 Status and logging 41Nortel VPN Router TroubleshootingLogsThe VPN Router has several logs that provide different levels of information. Th

Strany 168

42 Chapter 2 Status and loggingNN46110-602As the event log adds information, the oldest entries are overwritten. The event log retains the latest 20

Strany 169 - Troubleshooting Serial PPP

Chapter 2 Status and logging 43Nortel VPN Router TroubleshootingFigure 3 Capture and display filters5 You configure the capture filter and display

Strany 170

44 Chapter 2 Status and loggingNN46110-602Figure 4 Configure Display Entity b Select an Entity from the list.c Select a Subentity from the list.d

Strany 171 - PPP option settings

Chapter 2 Status and logging 45Nortel VPN Router TroubleshootingSystem logThe system log contains all system events that are considered significant

Strany 172

46 Chapter 2 Status and loggingNN46110-602• communications with servers •LDAP• Remote Authentication Dial-In User Service (RADIUS)Configuration logT

Strany 173 - System messages

47Nortel VPN Router TroubleshootingChapter 3Administrative tasksThis chapter describes administrative tasks that help you operate the VPN Router. Thes

Strany 174

48 Chapter 3 Administrative tasksNN46110-602RecoveryIn the unlikely event that there is a hard disk crash, use the Recovery window to configure a re

Strany 175 - ISAKMP messages

Chapter 3 Administrative tasks 49Nortel VPN Router TroubleshootingThis supplies a minimal configuration utility so that you can view the VPN Router

Strany 176 - (a.b.c.d)

5Nortel VPN Router TroubleshootingContentsPreface . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .

Strany 177

50 Chapter 3 Administrative tasksNN46110-602• Select Restore Factory Configuration, then click Restore to return the VPN Router to its original fact

Strany 178 - Branch office messages

Chapter 3 Administrative tasks 51Nortel VPN Router TroubleshootingYou can use a new factory default software image and file system to restore the VP

Strany 179 - SSL messages

52 Chapter 3 Administrative tasksNN46110-60212 Click Synchronize to immediately synchronize the primary and secondary disks. Thereafter, the disks a

Strany 180 - Database messages

Chapter 3 Administrative tasks 53Nortel VPN Router TroubleshootingYou must create a directory on the File Transfer Protocol (FTP) or Secure File Tra

Strany 181 - Security messages

54 Chapter 3 Administrative tasksNN46110-602To enable automatic backup when a file or a directory changes:1 Select Admin > Auto Backup. The Autom

Strany 182

Chapter 3 Administrative tasks 55Nortel VPN Router Troubleshooting7 To back up at certain intervals of time, click Interval and in the Interval text

Strany 183 - Entry is referenced [xxx]—xxx

56 Chapter 3 Administrative tasksNN46110-602Figure 7 Specific Automatic Backup window 14 To see the list of files for a directory, highlight the n

Strany 184 - Error deleting tree [xxx]—xxx

Chapter 3 Administrative tasks 57Nortel VPN Router Troubleshooting22 Click Backup to run the backup to each enabled server now. This action also syn

Strany 185

58 Chapter 3 Administrative tasksNN46110-602Backing up specific files and directoriesTo back up specific files and directories, with the option to d

Strany 186

Chapter 3 Administrative tasks 59Nortel VPN Router TroubleshootingStopping the backup of changes to specific files or directoriesTo stop backing up

Strany 187

6 ContentsNN46110-602Configuring SNMP traps to send notification when an IP address pool reaches the configured threshold . . . . . . . . . . . . . .

Strany 188

60 Chapter 3 Administrative tasksNN46110-602Disabling new loginsYou can prevent clients from connecting to the VPN Router without affecting the user

Strany 189

Chapter 3 Administrative tasks 61Nortel VPN Router Troubleshooting• Nortel Web site• your own FTP site if you previously downloaded the software fro

Strany 190

62 Chapter 3 Administrative tasksNN46110-602Before you upgrade your software, use one of the following methods to make sure there is enough availabl

Strany 191 - RADIUS accounting messages

Chapter 3 Administrative tasks 63Nortel VPN Router Troubleshooting5 Type 5 (Create A User Control Tunnel (IPsec) Profile).6 Enter the user ID that y

Strany 192

64 Chapter 3 Administrative tasksNN46110-602b Click Backup to start the backup immediately. This saves your entire hard drive, including the LDAP an

Strany 193 - <server-name> OK

Chapter 3 Administrative tasks 65Nortel VPN Router TroubleshootingFigure 9 shows an example upgrade to V04_80.114 from server 192.32.250.64. The fil

Strany 194

66 Chapter 3 Administrative tasksNN46110-602• User ID: type the login ID required to gain access to the FTP server where the new VPN Router software

Strany 195

Chapter 3 Administrative tasks 67Nortel VPN Router Troubleshooting— Response Timeout for RADIUS Accounting Server— External RADIUS Accounting Server

Strany 196

68 Chapter 3 Administrative tasksNN46110-6026 Select a system shutdown type of None and click OK.You have successfully upgraded your switch.

Strany 197

69Nortel VPN Router TroubleshootingChapter 4TroubleshootingThis chapter introduces the concepts and practices of advanced network configuration and tr

Strany 198 - Routing messages

Contents 7Nortel VPN Router TroubleshootingUsing SFTP to transfer backup files . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 59Sto

Strany 199

70 Chapter 4 TroubleshootingNN46110-602Troubleshooting remote access problems typically starts at the client end when the remote user cannot establi

Strany 200 - LoadOspfIntf Failed

Chapter 4 Troubleshooting 71Nortel VPN Router TroubleshootingMicrosoft Point-to-Point Tunneling Protocol (PPTP) Dial-Up Networking Monitor provides

Strany 201

72 Chapter 4 TroubleshootingNN46110-602Solving connectivity problemsThis section lists many of the common connectivity problems that occur and their

Strany 202 - RIP xxx: Circuit xxx created

Chapter 4 Troubleshooting 73Nortel VPN Router Troubleshooting1 Confirm that the modem is attached and working properly by running a terminal emulati

Strany 203 - RIP xxx: Circuit xxx deleted

74 Chapter 4 TroubleshootingNN46110-602Remote host not respondingCause: This indicates that the VPN Router never responded to the IPsec connection a

Strany 204 - Hardware messages

Chapter 4 Troubleshooting 75Nortel VPN Router TroubleshootingAction: Verify that the user name you entered is correct and retype the password before

Strany 205

76 Chapter 4 TroubleshootingNN46110-602Action: Click Connect to re-establish the extranet connection. If this works, the connection was probably los

Strany 206

Chapter 4 Troubleshooting 77Nortel VPN Router TroubleshootingAction: Validate that the VPN Client is configured with a DNS entry. For Windows NT 4.0

Strany 207 - Appendix D

78 Chapter 4 TroubleshootingNN46110-602Cannot access Web servers on the Internet after establishing a VPN Client connectionCause: For both PPTP and

Strany 208

Chapter 4 Troubleshooting 79Nortel VPN Router TroubleshootingAlternatively, on NT 4.0, Windows 98, and Windows 95, complete the following steps to c

Strany 209

8 ContentsNN46110-602System problems . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 96Solving r

Strany 210

80 Chapter 4 TroubleshootingNN46110-602• Start from the top down to go in the opposite direction, looking at PPP first and working down to the physi

Strany 211 - Database Editor, Version 1.0s

Chapter 4 Troubleshooting 81Nortel VPN Router TroubleshootingCheck the HDLC framingAssuming that the T1/V.35 interface is operating correctly, use t

Strany 212

82 Chapter 4 TroubleshootingNN46110-6024 If the PPP layer still does not come up, enable the interface debugger to generate large amounts of packet

Strany 213

Chapter 4 Troubleshooting 83Nortel VPN Router Troubleshooting• DHCP Server assigns IP addresses to clients• WINS Server provides a translation of th

Strany 214

84 Chapter 4 TroubleshootingNN46110-602The client system’s NetBIOS name must be unique in the private network to which the client is connecting. Do

Strany 215

Chapter 4 Troubleshooting 85Nortel VPN Router TroubleshootingThe renewal interval governs how often a client must reregister its name with the WINS

Strany 216

86 Chapter 4 TroubleshootingNN46110-602In the WINS mappings entry, enter a show database command. Note the entry for -__MSBROWSE__. This is the mach

Strany 217

Chapter 4 Troubleshooting 87Nortel VPN Router TroubleshootingTo specify a computer as the preferred master browser, set the parameter for IsDomainMa

Strany 218

88 Chapter 4 TroubleshootingNN46110-602When 10.1.2.3 broadcasts to find a network neighbor, it (incorrectly) sends to 10.255.255.255. Normal routing

Strany 219

Chapter 4 Troubleshooting 89Nortel VPN Router TroubleshootingAfter about 10 to 15 seconds, NetBIOS gives up on the primary interface, moves to the c

Strany 220

Contents 9Nortel VPN Router TroubleshootingViewing a packet capture output file on a PC . . . . . . . . . . . . . . . . . . . . . . . . . . . 125In

Strany 221 - VPN Router

90 Chapter 4 TroubleshootingNN46110-602You must create a connection definition for your initial Internet link through your service provider. A separ

Strany 222 - Configuring IPX

Chapter 4 Troubleshooting 91Nortel VPN Router TroubleshootingMy downloaded DNS servers for my tunnel connection do not workCause: The Microsoft Wind

Strany 223 - IPX client

92 Chapter 4 TroubleshootingNN46110-602• How to Troubleshoot TCP/IP Connectivity with Windows NT• Remote Access Service (RAS) Error Code List for Wi

Strany 224 - IPX group configuration

Chapter 4 Troubleshooting 93Nortel VPN Router Troubleshooting• For ActiveX Scripts, Java, and JavaScript*, you must enable both ActiveX and Java pro

Strany 225 - Figure 14 IPX topology

94 Chapter 4 TroubleshootingNN46110-602Clearing your Web browser cache when upgradingTo avoid problems when upgrading software revision levels, Nort

Strany 226

Chapter 4 Troubleshooting 95Nortel VPN Router TroubleshootingDocument not found messageCause: This message is returned when the HTTP server cannot f

Strany 227

96 Chapter 4 TroubleshootingNN46110-602Action: Close help windows after viewing them.Distorted background images Cause: In Netscape versions prior t

Strany 228

Chapter 4 Troubleshooting 97Nortel VPN Router TroubleshootingAction: If necessary, remove the front bezel as described in the installation guide, th

Strany 229

98 Chapter 4 TroubleshootingNN46110-602Action: Power-cycle the system using the green power button on the back of the VPN Router.Solving routing pro

Strany 230

Chapter 4 Troubleshooting 99Nortel VPN Router TroubleshootingSolving firewall problemsAn error occurred while parsing the policyDescription: The pol

Komentáře k této Příručce

Žádné komentáře